Files
Grav-Admin-Plugin/classes/controller.php

889 lines
25 KiB
PHP
Raw Normal View History

2014-08-05 13:06:38 -07:00
<?php
namespace Grav\Plugin;
use Grav\Common\Cache;
2014-10-01 22:28:16 +03:00
use Grav\Common\Config\Config;
2014-08-05 13:06:38 -07:00
use Grav\Common\Filesystem\Folder;
use Grav\Common\Grav;
2014-08-05 13:06:38 -07:00
use Grav\Common\Themes;
use Grav\Common\Uri;
use Grav\Common\Data;
use Grav\Common\Page;
use Grav\Common\Page\Collection;
use Grav\Common\User\User;
2015-04-27 13:37:22 +02:00
use Grav\Common\Utils;
use Grav\Common\Backup\ZipBackup;
use RocketTheme\Toolbox\File\JsonFile;
2014-08-05 13:06:38 -07:00
class AdminController
{
/**
* @var Grav
*/
public $grav;
2014-08-05 13:06:38 -07:00
/**
* @var string
*/
public $view;
/**
* @var string
*/
public $task;
/**
* @var string
*/
public $route;
/**
* @var array
*/
public $post;
/**
* @var Admin
*/
protected $admin;
/**
* @var string
*/
protected $redirect;
/**
* @var int
*/
protected $redirectCode;
/**
* @param Grav $grav
2014-08-05 13:06:38 -07:00
* @param string $view
* @param string $task
* @param string $route
* @param array $post
*/
public function __construct(Grav $grav, $view, $task, $route, $post)
2014-08-05 13:06:38 -07:00
{
$this->grav = $grav;
2014-08-05 13:06:38 -07:00
$this->view = $view;
$this->task = $task ? $task : 'display';
$this->post = $this->getPost($post);
$this->route = $route;
$this->admin = $this->grav['admin'];
2014-08-05 13:06:38 -07:00
}
/**
* Performs a task.
*/
public function execute()
{
$success = false;
$method = 'task' . ucfirst($this->task);
if (method_exists($this, $method)) {
try {
$success = call_user_func(array($this, $method));
} catch (\RuntimeException $e) {
$success = true;
$this->admin->setMessage($e->getMessage());
}
// Grab redirect parameter.
$redirect = isset($this->post['_redirect']) ? $this->post['_redirect'] : null;
unset($this->post['_redirect']);
2014-08-05 13:06:38 -07:00
// Redirect if requested.
if ($redirect) {
$this->setRedirect($redirect);
}
}
return $success;
}
public function redirect()
{
if (!$this->redirect) {
return;
}
$base = $this->admin->base;
2014-12-10 10:23:22 -07:00
$path = trim(substr($this->redirect, 0, strlen($base)) == $base ? substr($this->redirect, strlen($base)) : $this->redirect, '/');
2014-08-05 13:06:38 -07:00
$this->grav->redirect($base . '/' . preg_replace('|/+|', '/', $path), $this->redirectCode);
2014-08-05 13:06:38 -07:00
}
/**
* Handle login.
*
* @return bool True if the action was performed.
*/
protected function taskLogin()
{
if ($this->admin->authenticate($this->post)) {
$this->admin->setMessage('You have been logged in.');
} else {
$this->admin->setMessage('Login failed.');
}
2014-08-05 13:06:38 -07:00
return true;
}
/**
* Handle logout.
*
* @return bool True if the action was performed.
*/
protected function taskLogout()
{
$this->admin->session()->invalidate()->start();
$this->admin->setMessage('You have been logged out.');
$this->setRedirect('/');
return true;
}
2015-04-20 16:01:20 +02:00
protected function taskForgot()
{
$data = $this->post;
$username = isset($data['username']) ? $data['username'] : '';
$user = !empty($username) ? User::load($username) : null;
if (!isset($this->grav['Email'])) {
$this->admin->setMessage('Cannot reset password. This site is not configured to send emails.');
$this->setRedirect('/');
return true;
}
if (!$user || !$user->exists()) {
$this->admin->setMessage('User with username \'' . $username . '\' does not exist.');
$this->setRedirect('/forgot');
return true;
}
if (empty($user->email)) {
$this->admin->setMessage('Cannot reset password for \'' . $username . '\', no email address is set.');
$this->setRedirect('/forgot');
return true;
}
$token = md5(uniqid(mt_rand(), true));
$expire = time() + 604800; // next week
$user->reset = $token . '::' . $expire;
$user->save();
$author = $this->grav['config']->get('site.author.name', '');
$fullname = $user->fullname ?: $username;
$reset_link = rtrim($this->grav['uri']->rootUrl(true), '/') . '/' . trim($this->admin->base, '/') . '/reset/task:reset/user:' . $username . '/token:' . $token;
$from = $this->grav['config']->get('site.author.email', 'noreply@getgrav.org');
$to = $user->email;
$subject = $this->grav['config']->get('site.title', 'Website') . ' password reset';
$body = $this->grav['twig']->processString('{% include "email/reset.html.twig" %}', [
'name' => $fullname,
'author' => $author,
'reset_link' =>$reset_link
]);
$message = $this->grav['Email']->message($subject, $body, 'text/html')
->setFrom($from)
->setTo($to);
$sent = $this->grav['Email']->send($message);
if ($sent < 1) {
$this->admin->setMessage('Failed to email instructions, please try again later.');
} else {
$this->admin->setMessage('Instructions to reset your password have been sent by email.');
}
$this->setRedirect('/');
return true;
}
public function taskReset()
{
$data = $this->post;
if (isset($data['password'])) {
$username = isset($data['username']) ? $data['username'] : null;
$user = !empty($username) ? User::load($username) : null;
$password = isset($data['password']) ? $data['password'] : null;
$token = isset($data['token']) ? $data['token'] : null;
if (!empty($user) && $user->exists() && !empty($user->reset)) {
list($good_token, $expire) = explode('::', $user->reset);
if ($good_token === $token) {
if (time() > $expire) {
$this->admin->setMessage('Reset link has expired, please try again.');
$this->setRedirect('/forgot');
return true;
}
unset($user->hashed_password);
unset($user->reset);
$user->password = $password;
$user->save();
$this->admin->setMessage('Password has been reset.');
$this->setRedirect('/');
return true;
}
}
$this->admin->setMessage('Invalid reset link used, please try again.');
$this->setRedirect('/forgot');
return true;
} else {
$user = $this->grav['uri']->param('user');
$token = $this->grav['uri']->param('token');
if (empty($user) || empty($token)) {
$this->admin->setMessage('Invalid reset link used, please try again.');
$this->setRedirect('/forgot');
return true;
}
$this->admin->forgot = [ 'username' => $user, 'token' => $token ];
}
return true;
}
protected function taskClearCache()
{
$results = Cache::clearCache('standard');
if (count($results) > 0) {
$this->admin->json_response = ['success', 'Cache cleared'];
} else {
$this->admin->json_response = ['error', 'Error clearing cache'];
}
2014-08-05 13:06:38 -07:00
return true;
}
2015-04-27 13:37:22 +02:00
protected function taskBackup()
{
$download = $this->grav['uri']->param('download');
if ($download) {
Utils::download(base64_decode(urldecode($download)), true);
}
$log = JsonFile::instance($this->grav['locator']->findResource("log://backup.log", true, true));
$backup = ZipBackup::backup();
$download = urlencode(base64_encode($backup));
$url = rtrim($this->grav['uri']->rootUrl(true), '/') . '/' . trim($this->admin->base, '/') . '/task:backup/download:' . $download;
$log->content([
'time' => time(),
'location' => $backup
]);
$log->save();
$this->admin->json_response = [
'status' => 'success',
'message' => 'Your backup is ready for download. <a href="'.$url.'" class="button">Download backup</a>',
'toastr' => [
'timeOut' => 0,
'closeButton' => true
]
];
return true;
}
protected function taskFilterPages()
{
$data = $this->post;
$flags = !empty($data['flags']) ? array_map('strtolower', explode(',', $data['flags'])) : [];
$queries = !empty($data['query']) ? explode(',', $data['query']) : [];
$collection = $this->grav['pages']->all();
if (count($flags)) {
if (in_array('modular', $flags))
$collection = $collection->modular();
if (in_array('visible', $flags))
$collection = $collection->visible();
if (in_array('routable', $flags))
$collection = $collection->routable();
}
if (!empty($queries)) {
foreach ($collection as $page) {
foreach ($queries as $query) {
$query = trim($query);
// $page->content();
if (stripos($page->getRawContent(), $query) === false && stripos($page->title(), $query) === false) {
$collection->remove($page);
}
}
}
}
$this->admin->json_response = ['success', 'Pages filtered'];
$this->admin->collection = $collection;
}
2014-09-22 15:49:53 -06:00
protected function taskListmedia()
{
$page = $this->admin->page(true);
2014-09-22 17:13:19 -06:00
if (!$page) {
$this->admin->json_response = ['error', 'No Page found'];
2014-10-01 22:28:16 +03:00
return false;
2014-09-22 17:13:19 -06:00
}
$media_list = array();
2014-12-10 10:23:22 -07:00
foreach ($page->media()->all() as $name => $media) {
$media_list[$name] = ['url' => $media->cropZoom(150, 100)->url(),'size' => $media->get('size')];
2014-09-22 15:49:53 -06:00
}
$this->admin->media = $media_list;
return true;
}
2014-09-22 16:35:11 -06:00
protected function taskAddmedia()
{
$page = $this->admin->page(true);
2014-10-01 22:28:16 +03:00
/** @var Config $config */
2014-09-22 16:35:11 -06:00
$config = $this->grav['config'];
2014-10-07 15:32:07 -06:00
if (!isset($_FILES['file']['error']) || is_array($_FILES['file']['error'])) {
$this->admin->json_response = ['error', 'Invalid Parameters'];
return;
}
2014-09-22 16:35:11 -06:00
2014-10-07 15:32:07 -06:00
// Check $_FILES['file']['error'] value.
switch ($_FILES['file']['error']) {
case UPLOAD_ERR_OK:
break;
case UPLOAD_ERR_NO_FILE:
$this->admin->json_response = ['error', 'No files sent'];
2014-09-22 16:35:11 -06:00
return;
2014-10-07 15:32:07 -06:00
case UPLOAD_ERR_INI_SIZE:
case UPLOAD_ERR_FORM_SIZE:
$this->admin->json_response = ['error', 'Exceeded filesize limit.'];
return;
default:
$this->admin->json_response = ['error', 'Unkown errors'];
return;
}
2014-09-22 16:35:11 -06:00
2014-10-07 15:32:07 -06:00
// You should also check filesize here.
if ($_FILES['file']['size'] > 1000000) {
$this->admin->json_response = ['error', 'Exceeded filesize limit.'];
return;
2014-09-22 16:35:11 -06:00
}
2014-10-07 15:32:07 -06:00
// Check extension
$fileParts = pathinfo($_FILES['file']['name']);
$fileExt = strtolower($fileParts['extension']);
// If not a supported type, return
if (!$config->get("media.{$fileExt}")) {
$this->admin->json_response = ['error', 'Unsupported file type: '.$fileExt];
return;
}
// Upload it
2014-12-10 10:23:22 -07:00
if (!move_uploaded_file($_FILES['file']['tmp_name'], sprintf('%s/%s', $page->path(), $_FILES['file']['name']))) {
2014-10-07 15:32:07 -06:00
$this->admin->json_response = ['error', 'Failed to move uploaded file.'];
return;
}
$this->admin->json_response = ['success', 'File uploaded successfully'];
2014-09-22 17:13:19 -06:00
return;
}
protected function taskDelmedia()
{
2014-09-22 17:27:48 -06:00
$page = $this->admin->page(true);
if (!$page) {
$this->admin->json_response = ['error', 'No Page found'];
2014-10-01 22:28:16 +03:00
return false;
2014-09-22 17:27:48 -06:00
}
2014-09-22 17:13:19 -06:00
2014-09-22 17:27:48 -06:00
$filename = !empty($this->post['filename']) ? $this->post['filename'] : null;
if ($filename) {
$targetPath = $page->path().'/'.$filename;
if (file_exists($targetPath)) {
2014-12-10 10:23:22 -07:00
if (unlink($targetPath)) {
$this->admin->json_response = ['success', 'File deleted: '.$filename];
} else {
$this->admin->json_response = ['error', 'File could not be deleted: '.$filename];
}
2014-09-22 17:27:48 -06:00
} else {
$this->admin->json_response = ['error', 'File not found: '.$filename];
2014-09-22 17:27:48 -06:00
}
} else {
$this->admin->json_response = ['error', 'No file found'];
}
return true;
2014-09-22 16:35:11 -06:00
}
2014-08-05 13:06:38 -07:00
/**
* Enable plugin.
*
* @return bool True if the action was performed.
*/
public function taskEnable()
{
if ($this->view != 'plugins') {
return false;
}
// Filter value and save it.
$this->post = array('enabled' => 1, '_redirect' => 'plugins');
$obj = $this->prepareData();
$obj->save();
$this->admin->setMessage('Successfully enabled plugin');
return true;
}
/**
* Enable plugin.
*
* @return bool True if the action was performed.
*/
public function taskDisable()
{
if ($this->view != 'plugins') {
return false;
}
// Filter value and save it.
$this->post = array('enabled' => 0, '_redirect' => 'plugins');
2014-08-05 13:06:38 -07:00
$obj = $this->prepareData();
$obj->save();
$this->admin->setMessage('Successfully disabled plugin');
2014-08-05 13:06:38 -07:00
return true;
}
/**
* Set default theme.
*
* @return bool True if the action was performed.
*/
public function taskActivate()
2014-08-05 13:06:38 -07:00
{
if ($this->view != 'themes') {
return false;
}
$this->post = array('_redirect' => 'themes');
2014-08-05 13:06:38 -07:00
// Make sure theme exists (throws exception)
$name = $this->route;
$this->grav['themes']->get($name);
2014-08-05 13:06:38 -07:00
// Store system configuration.
$system = $this->admin->data('system');
$system->set('pages.theme', $name);
$system->save();
// Force configuration reload and save.
/** @var Config $config */
$config = $this->grav['config'];
2014-08-05 13:06:38 -07:00
$config->reload()->save();
// TODO: find out why reload and save doesn't always update the object itself (and remove this workaround).
$config->set('system.pages.theme', $name);
$this->admin->setMessage('Successfully changed default theme.');
return true;
}
/**
* Handles installing plugins and themes
*
* @return bool True is the action was performed
*/
public function taskInstall()
{
2015-04-13 21:37:12 +02:00
require_once __DIR__ . '/gpm.php';
$package = $this->route;
$result = \Grav\Plugin\Admin\Gpm::install($package, []);
if ($result) {
$this->admin->setMessage("Installation successful.");
} else {
$this->admin->setMessage("Installation failed.");
}
$this->post = array('_redirect' => $this->view . '/' . $this->route);
return true;
}
/**
* Handles updating plugins and themes
*
* @return bool True is the action was performed
*/
public function taskUpdate()
{
require_once __DIR__ . '/gpm.php';
$package = $this->route;
// Update multi mode
if (!$package) {
$package = [];
if ($this->view === 'plugins' || $this->view === 'update') {
$package = $this->admin->gpm()->getUpdatablePlugins();
}
if ($this->view === 'themes' || $this->view === 'update') {
$package = array_merge($package, $this->admin->gpm()->getUpdatableThemes());
}
}
$result = \Grav\Plugin\Admin\Gpm::update($package, []);
if ($this->view === 'update') {
if ($result) {
$this->admin->json_response = ['success', 'Everything updated'];
} else {
$this->admin->json_response = ['error', 'Updates failed'];
}
} else {
if ($result) {
$this->admin->setMessage("Installation successful.");
} else {
$this->admin->setMessage("Installation failed.");
}
$this->post = array('_redirect' => $this->view . '/' . $this->route);
}
return true;
}
/**
* Handles uninstalling plugins and themes
*
* @return bool True is the action was performed
*/
public function taskUninstall()
{
require_once __DIR__ . '/gpm.php';
$package = $this->route;
2015-04-13 21:37:12 +02:00
$result = \Grav\Plugin\Admin\Gpm::uninstall($package, []);
if ($result) {
$this->admin->setMessage("Uninstall successful.");
} else {
$this->admin->setMessage("Uninstall failed.");
}
$this->post = array('_redirect' => $this->view);
return true;
}
2014-08-05 13:06:38 -07:00
/**
* Handles form and saves the input data if its valid.
*
* @return bool True if the action was performed.
*/
public function taskSave()
{
$data = $this->post;
// Special handler for pages data.
if ($this->view == 'pages') {
/** @var Page\Pages $pages */
$pages = $this->grav['pages'];
2014-08-05 13:06:38 -07:00
// Find new parent page in order to build the path.
$route = !isset($data['route']) ? dirname($this->admin->route) : $data['route'];
$parent = $route && $route != '/' ? $pages->dispatch($route, true) : $pages->root();
2014-08-05 13:06:38 -07:00
$obj = $this->admin->page(true);
// Change parent if needed and initialize move (might be needed also on ordering/folder change).
$obj = $obj->move($parent);
$this->preparePage($obj);
// Reset slug and route. For now we do not support slug twig variable on save.
$obj->slug('');
} else {
// Handle standard data types.
$obj = $this->prepareData();
}
if ($obj) {
$obj->validate();
$obj->filter();
$obj->save();
$this->admin->setMessage('Successfully saved');
2014-08-05 13:06:38 -07:00
}
2014-10-07 12:12:21 +03:00
if ($this->view != 'pages') {
// Force configuration reload.
/** @var Config $config */
$config = $this->grav['config'];
$config->reload();
if ($this->view === 'users') {
$this->grav['user']->merge(User::load($this->admin->route)->toArray());
}
2014-10-07 12:12:21 +03:00
}
2014-08-05 13:06:38 -07:00
// Redirect to new location.
if ($obj instanceof Page\Page && $obj->route() != $this->admin->route()) {
$this->setRedirect($this->view . '/' . $obj->route());
}
return true;
}
/**
* Continue to the new page.
*
* @return bool True if the action was performed.
*/
public function taskContinue()
{
2014-10-10 15:25:07 +03:00
if ($this->view == 'users') {
$this->setRedirect("{$this->view}/{$this->post['username']}");
return true;
}
2014-08-05 13:06:38 -07:00
if ($this->view != 'pages') {
return false;
}
$data = $this->post;
2014-09-17 11:54:57 +03:00
$route = $data['route'] != '/' ? $data['route'] : '';
2014-10-10 11:57:57 +03:00
$folder = ltrim($data['folder'], '_');
if (!empty($data['modular'])) {
$folder = '_' . $folder;
}
2014-08-05 13:06:38 -07:00
$path = $route . '/' . $folder;
2014-09-17 11:54:57 +03:00
$this->admin->session()->{$path} = $data;
$this->setRedirect("{$this->view}/{$path}");
2014-08-05 13:06:38 -07:00
return true;
}
/**
* Save page as a new copy.
*
* @return bool True if the action was performed.
* @throws \RuntimeException
*/
protected function taskCopy()
{
// Only applies to pages.
if ($this->view != 'pages') {
return false;
}
try {
/** @var Page\Pages $pages */
$pages = $this->grav['pages'];
2014-08-05 13:06:38 -07:00
$data = $this->post;
// Find new parent page in order to build the path.
$parent = empty($data['route']) ? $pages->root() : $pages->dispatch($data['route'], true);
// And then get the current page.
$page = $this->admin->page(true);
// Make a copy of the current page and fill the updated information into it.
$page = $page->copy($parent);
$this->preparePage($page);
// Deal with folder naming conflicts, but limit number of searches to 99.
$break = 99;
while ($break > 0 && file_exists($page->filePath())) {
$break--;
$match = preg_split('/-(\d+)$/', $page->path(), 2, PREG_SPLIT_DELIM_CAPTURE);
$page->path($match[0] . '-' . (isset($match[1]) ? (int) $match[1] + 1 : 2));
// Reset slug and route. For now we do not support slug twig variable on save.
$page->slug('');
}
// Validation, type filtering and saving the changes.
$page->validate();
$page->filter();
$page->save();
// Enqueue message and redirect to new location.
$this->admin->setMessage('Successfully copied');
2014-08-05 13:06:38 -07:00
$this->setRedirect($this->view . '/' . $page->route());
} catch (\Exception $e) {
throw new \RuntimeException('Copying page failed on error: ' . $e->getMessage());
}
return true;
}
/**
* Reorder pages.
*
* @return bool True if the action was performed.
*/
protected function taskReorder()
{
// Only applies to pages.
if ($this->view != 'pages') {
return false;
}
$this->admin->setMessage('Reordering was successful');
return true;
}
/**
* Delete page.
*
* @return bool True if the action was performed.
* @throws \RuntimeException
*/
protected function taskDelete()
{
// Only applies to pages.
if ($this->view != 'pages') {
return false;
}
/** @var Uri $uri */
$uri = $this->grav['uri'];
2014-08-05 13:06:38 -07:00
try {
$page = $this->admin->page();
Folder::delete($page->path());
2014-09-30 17:41:45 -06:00
// Set redirect to either referrer or pages list.
2014-08-05 13:06:38 -07:00
$redirect = $uri->referrer();
if ($redirect == $uri->route()) {
2014-09-30 17:41:45 -06:00
$redirect = 'pages';
2014-08-05 13:06:38 -07:00
}
$this->admin->setMessage('Successfully deleted');
2014-08-05 13:06:38 -07:00
$this->setRedirect($redirect);
} catch (\Exception $e) {
throw new \RuntimeException('Deleting page failed on error: ' . $e->getMessage());
}
return true;
}
/**
* Prepare and return POST data.
*
* @param array $post
* @return array
*/
protected function &getPost($post)
{
unset($post['task']);
// Decode JSON encoded fields and merge them to data.
if (isset($post['_json'])) {
$post = array_merge_recursive($post, $this->jsonDecode($post['_json']));
unset($post['_json']);
}
return $post;
}
/**
* Recursively JSON decode data.
*
* @param array $data
* @return array
*/
protected function jsonDecode(array $data)
{
foreach ($data as &$value) {
if (is_array($value)) {
$value = $this->jsonDecode($value);
} else {
$value = json_decode($value, true);
}
}
return $data;
}
2014-12-10 10:23:22 -07:00
protected function setRedirect($path, $code = 303)
{
2014-08-05 13:06:38 -07:00
$this->redirect = $path;
$this->code = $code;
}
protected function prepareData()
{
$type = trim("{$this->view}/{$this->admin->route}", '/');
$data = $this->admin->data($type, $this->post);
return $data;
}
protected function preparePage(\Grav\Common\Page\Page $page)
{
$input = $this->post;
$order = max(0, (int) isset($input['order']) ? $input['order'] : $page->value('order'));
$ordering = $order ? sprintf('%02d.', $order) : '';
$slug = empty($input['folder']) ? $page->value('folder') : (string) $input['folder'];
$page->folder($ordering . $slug);
if (isset($input['type'])) {
2014-10-08 19:55:50 +03:00
$type = (string) $input['type'];
$name = preg_replace('|.*/|', '', $type) . '.md';
$page->name($name);
$page->template($type);
2014-10-08 15:14:46 +03:00
}
2014-09-20 15:34:35 -06:00
// special case for Expert mode build the raw, unset content
if (isset($input['frontmatter']) && isset($input['content'])) {
$page->raw("---\n" . (string) $input['frontmatter'] . "\n---\n" . (string) $input['content']);
unset($input['content']);
2014-08-05 13:06:38 -07:00
}
if (isset($input['header'])) {
$page->header((object) $input['header']);
}
// Fill content last because of it also renders the output.
if (isset($input['content'])) {
$page->content((string) $input['content']);
}
}
}